Post cover image

September 18, 2026

CVE-2026–2619: How a Read-Only GitLab Auditor Could Modify Vulnerability Flags

An authorization flaw in GitLab’s AI detection API, the evidence behind my report, and the permission change that fixed it.

By KabishDahal

6 min read